Dynamic Group VPN Firewall Policy Updates Without Reboot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN firewall security policies are configured statically, making real-time changes challenging, especially in dynamic group VPN environments where member access is dynamic and requires immediate policy updates.

Innovation Solution

Implementing a method where a server device receives registration requests from member devices, sends initial security policy data, and pushes dynamic policy changes as subsets of template policies, allowing member devices to apply these changes to incoming traffic without rebooting, enabling real-time firewall security policy updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static configuration method is used for VPN firewall security policies, then system stability is maintained, but real-time policy updates cannot be achieved and manual intervention is required

Engineering Contradiction:
Improvesystem stabilityVSAvoidreal-time policy update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static configuration system into a dynamic one by introducing real-time policy update mechanisms. The server can push policy updates to member devices dynamically, and members can pull updates on demand, enabling the system to adapt to changing security requirements without manual reconfiguration while maintaining operational stability through structured update protocols

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where member devices can request policy updates by sending pull requests to the server, and the server can push updates when policy changes occur. This bidirectional communication ensures that policy configurations are synchronized across the group VPN while maintaining system stability through controlled update cycles

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If manual configuration changes are made by network administrators, then policy accuracy is maintained, but response time is delayed and productivity is reduced

Engineering Contradiction:
Improvepolicy configuration accuracyVSAvoidpolicy update speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent enables self-service policy updates where the system automatically distributes policy configurations from the server to member devices without requiring manual administrator intervention for each update. The server pushes updates automatically when policies change, and members can pull updates on demand, significantly improving update speed while maintaining accuracy through the centralized policy management architecture

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by having the server prepare and store policy updates ready for distribution. When a policy change is made, the server can immediately push the pre-prepared update to all member devices, eliminating the delay of manual configuration and ensuring rapid, accurate policy deployment across the entire group VPN

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If static security policies are used, then device complexity is reduced, but adaptability to dynamic group VPN membership is insufficient

Engineering Contradiction:
Improveconfiguration management simplicityVSAvoiddynamic membership support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal policy management system where a single server manages security policies for multiple dynamic members of the group VPN. The server can serve multiple members with individualized policies while maintaining a centralized configuration repository, enabling the system to adapt to changing membership without increasing individual device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a server as an intermediary between policy definitions and member devices. The server acts as a mediator that receives policy updates, processes them, and distributes them to appropriate members, simplifying the complexity by centralizing management logic while enabling dynamic adaptability through the intermediary's coordination capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9935980B2Adding firewall security policy dynamically to support group VPN
Publication Date: 2018.04.03 JUNIPER NETWORKS INC
  • US9935980B2 patent drawing
  • US9935980B2 patent drawing
  • US9935980B2 patent drawing

AI summary

A server device receives, from a member device, a registration request for a group virtual private network (VPN) and provides an initial firewall security policy for the group VPN. The server device receives instructions for a policy configuration change and sends, to the member device, a push message that includes dynamic policies to implement the policy configuration change. The dynamic policies are implemented as a subset of a template policy. The member device receives the push message with the dynamic policies, associates the dynamic policies with the template policy, and applies the initial security policy data and the dynamic policies to incoming traffic without the need for a reboot of the member device.